US2025080531A1PendingUtilityA1

Identity authentication method, personal security kernel node, device, and medium

Assignee: TENCENT TECH SHENZHEN CO LTDPriority: Jan 16, 2019Filed: Nov 14, 2024Published: Mar 6, 2025
Est. expiryJan 16, 2039(~12.5 yrs left)· nominal 20-yr term from priority
H04L 9/50H04L 9/3247G06F 21/31H04L 63/0884H04L 9/3239H04L 9/3213G06F 21/33G06Q 40/08G06F 21/64G06F 21/45G06F 21/41
72
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The present disclosure provides an identity authentication method, a personal security kernel node, a device, and a medium. The personal security kernel node is part of an identity authentication system, the identity authentication system further comprising a relying party node and a user identity credential certifier node. The method includes: obtaining an identity authentication assurance level corresponding to a service provided by a relying party; determining, according to the identity authentication assurance level, a user identity credential used by a user for the service; transmitting the user identity credential to a user identity credential certifier node through a relying party node, so that the user identity credential certifier node performs user identity credential authentication; and performing the service with the relying party node. According to the embodiments of the present disclosure, security of user identity assets can be improved during identity authentication.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . An identity authentication method, performed by a computer device acting as a personal security kernel node of an identity authentication system, the identity authentication system further comprising a relying party node, a service-level user identity credential certifier node and a legal user identity credential certifier node, the method comprising:
 obtaining an identity authentication assurance level corresponding to a service provided by a relying party;   determining, according to the identity authentication assurance level, a user identity credential used by a user for the service;   in accordance with a determination that the user identity credential is a legal identity credential, transmitting the user identity credential to the legal user identity credential certifier node via the relying party node, wherein the legal user identity credential certifier node is configured to perform user identity credential authentication for the user for the service;   in accordance with a determination that the user identity credential is a service-level user identity credential, transmitting the user identity credential to the service-level user identity credential certifier node via the relying party node, wherein the service-level user identity credential certifier node is configured to perform user identity credential authentication for the user for the service; and   performing the service with the relying party node in response to reception of a receipt indicating that the user identity credential authentication succeeds from one of the legal user identity credential certifier node and the service-level user identity credential certifier node.   
     
     
         2 . The method according to  claim 1 , wherein the identity authentication system further comprises a relying party qualification certifier node, and the method further comprises:
 obtaining relying party qualification information; and   transmitting the relying party qualification information to the relying party qualification certifier node, wherein the relying party qualification certifier node performs relying party qualification authentication; and   the obtaining an identity authentication assurance level corresponding to a service provided by a relying party comprises:   obtaining, in response to receiving a reply indicating that the relying party qualification authentication succeeds from the relying party qualification certifier node, the identity authentication assurance level corresponding to the service provided by the relying party.   
     
     
         3 . The method according to  claim 1 , wherein the determining, according to the identity authentication assurance level, a user identity credential used by a user for the service comprises:
 presenting candidate user identity credentials that match the identity authentication assurance level and the service provided by the relying party; and   receiving a candidate user identity credential selected by the user, and determining the candidate user identity credential selected by the user as the user identity credential used by the user for the service.   
     
     
         4 . The method according to  claim 3 , wherein the identity authentication system further comprises a peer certifier node, and after the obtaining an identity authentication assurance level corresponding to a service provided by a relying party, the method further comprises:
 presenting peer certifier identifiers that match the identity authentication assurance level and the service provided by the relying party;   receiving a peer certifier identifier selected by the user, and using the selected peer certifier identifier as authorization of the user to a peer certifier corresponding to the peer certifier identifier;   transmitting the peer certifier identifier selected by the user to the relying party node, so that the relying party node transmits a verification request to the peer certifier corresponding to the peer certifier identifier; and   performing the service with the relying party node in a case that a receipt indicating successful peer authentication transmitted by the peer certifier through the relying party node is received.   
     
     
         5 . The method according to  claim 2 , wherein before the obtaining relying party qualification information, the method further comprises:
 generating a pair of public and private keys of the user for the user in response to received user information, storing the private key, and issuing the public key; and   after the performing the service with the relying party node, the method further comprises:   signing a service performance result with the private key of the user, and transmitting the service performance result and the signature together to the relying party node, so that the relying party node verifies the signature by using the public key of the user.   
     
     
         6 . The method according to  claim 2 , wherein the relying party qualification certifier node comprises a relying party identity authenticator node;
 the relying party qualification information comprises a relying party identity certificate and an identifier of a relying party identity authenticator node that issues the relying party identity certificate; and   the transmitting the relying party qualification information to the relying party qualification certifier node, so that the relying party qualification certifier node performs relying party qualification authentication comprises: transmitting the relying party identity certificate to the relying party identity authenticator node corresponding to the identifier of the relying party identity authenticator node, so that the relying party qualification certifier node performs relying party identity authentication.   
     
     
         7 . The method according to  claim 2 , wherein the relying party qualification certifier node comprises a security credential authenticator node;
 the relying party qualification information comprises a relying party security credential and an identifier of a security credential authenticator node that issues the relying party security credential; and   the transmitting the relying party qualification information to the relying party qualification certifier node, so that the relying party qualification certifier node performs relying party qualification authentication comprises: transmitting the relying party security credential to the security credential authenticator node corresponding to the identifier of the security credential authenticator node, so that the relying party qualification certifier node performs relying party security credential authentication.   
     
     
         8 . The method according to  claim 1 , wherein the determining, according to the identity authentication assurance level, a user identity credential used by a user for the service comprises:
 searching a correspondence table of identity authentication assurance levels, services, and user identity credentials, to determine user identity credentials that match the identity authentication assurance level and the service provided by the relying party;   presenting the determined user identity credentials as candidate user identity credentials to the user of the service; and   determining one of the candidate user identity credentials selected by the user of the service as the user identity credential used by the user for the service.   
     
     
         9 . A computer device acting as a personal security kernel node of an identity authentication system to perform an identity authentication method, the identity authentication system further comprising a relying party node and a user identity credential certifier node, the computer device comprising:
 a memory, storing computer-readable instructions; and   a processor, configured to execute the computer-readable instructions stored in the memory, to perform a plurality of operations including:   obtaining an identity authentication assurance level corresponding to a service provided by a relying party;   determining, according to the identity authentication assurance level, a user identity credential used by a user for the service;   in accordance with a determination that the user identity credential is a legal identity credential, transmitting the user identity credential to the legal user identity credential certifier node via the relying party node, wherein the legal user identity credential certifier node is configured to perform user identity credential authentication for the user for the service;   in accordance with a determination that the user identity credential is a service-level user identity credential, transmitting the user identity credential to the service-level user identity credential certifier node via the relying party node, wherein the service-level user identity credential certifier node is configured to perform user identity credential authentication for the user for the service; and   performing the service with the relying party node in response to reception of a receipt indicating that the user identity credential authentication succeeds from one of the legal user identity credential certifier node and the service-level user identity credential certifier node.   
     
     
         10 . The computer device according to  claim 9 , wherein the identity authentication system further comprises a relying party qualification certifier node, and the method further comprises:
 obtaining relying party qualification information; and   transmitting the relying party qualification information to the relying party qualification certifier node, wherein the relying party qualification certifier node performs relying party qualification authentication; and   the obtaining an identity authentication assurance level corresponding to a service provided by a relying party comprises:   obtaining, in response to receiving a reply indicating that the relying party qualification authentication succeeds from the relying party qualification certifier node, the identity authentication assurance level corresponding to the service provided by the relying party.   
     
     
         11 . The computer device according to  claim 9 , wherein the determining, according to the identity authentication assurance level, a user identity credential used by a user for the service comprises:
 presenting candidate user identity credentials that match the identity authentication assurance level and the service provided by the relying party; and   receiving a candidate user identity credential selected by the user, and determining the candidate user identity credential selected by the user as the user identity credential used by the user for the service.   
     
     
         12 . The computer device according to  claim 11 , wherein the identity authentication system further comprises a peer certifier node, and after the obtaining an identity authentication assurance level corresponding to a service provided by a relying party, the method further comprises:
 presenting peer certifier identifiers that match the identity authentication assurance level and the service provided by the relying party;   receiving a peer certifier identifier selected by the user, and using the selected peer certifier identifier as authorization of the user to a peer certifier corresponding to the peer certifier identifier;   transmitting the peer certifier identifier selected by the user to the relying party node, so that the relying party node transmits a verification request to the peer certifier corresponding to the peer certifier identifier; and   performing the service with the relying party node in a case that a receipt indicating successful peer authentication transmitted by the peer certifier through the relying party node is received.   
     
     
         13 . The computer device according to  claim 10 , wherein before the obtaining relying party qualification information, the method further comprises:
 generating a pair of public and private keys of the user for the user in response to received user information, storing the private key, and issuing the public key; and   after the performing the service with the relying party node, the method further comprises:   signing a service performance result with the private key of the user, and transmitting the service performance result and the signature together to the relying party node, so that the relying party node verifies the signature by using the public key of the user.   
     
     
         14 . The computer device according to  claim 10 , wherein the relying party qualification certifier node comprises a relying party identity authenticator node;
 the relying party qualification information comprises a relying party identity certificate and an identifier of a relying party identity authenticator node that issues the relying party identity certificate; and   the transmitting the relying party qualification information to the relying party qualification certifier node, so that the relying party qualification certifier node performs relying party qualification authentication comprises: transmitting the relying party identity certificate to the relying party identity authenticator node corresponding to the identifier of the relying party identity authenticator node, so that the relying party qualification certifier node performs relying party identity authentication.   
     
     
         15 . The computer device according to  claim 10 , wherein the relying party qualification certifier node comprises a security credential authenticator node;
 the relying party qualification information comprises a relying party security credential and an identifier of a security credential authenticator node that issues the relying party security credential; and   the transmitting the relying party qualification information to the relying party qualification certifier node, so that the relying party qualification certifier node performs relying party qualification authentication comprises: transmitting the relying party security credential to the security credential authenticator node corresponding to the identifier of the security credential authenticator node, so that the relying party qualification certifier node performs relying party security credential authentication.   
     
     
         16 . The computer device according to  claim 9 , wherein the determining, according to the identity authentication assurance level, a user identity credential used by a user for the service comprises:
 searching a correspondence table of identity authentication assurance levels, services, and user identity credentials, to determine user identity credentials that match the identity authentication assurance level and the service provided by the relying party;   presenting the determined user identity credentials as candidate user identity credentials to the user of the service; and   determining one of the candidate user identity credentials selected by the user of the service as the user identity credential used by the user for the service.   
     
     
         17 . A non-transitory computer readable medium, storing computer-readable instructions, the computer-readable instructions, when executed by a processor of a computer device acting as a personal security kernel node of an identity authentication system that further comprises a relying party node and a user identity credential certifier node, causing the computer device to perform a plurality of operations including:
 obtaining an identity authentication assurance level corresponding to a service provided by a relying party;   determining, according to the identity authentication assurance level, a user identity credential used by a user for the service;   in accordance with a determination that the user identity credential is a legal identity credential, transmitting the user identity credential to the legal user identity credential certifier node via the relying party node, wherein the legal user identity credential certifier node is configured to perform user identity credential authentication for the user for the service;   in accordance with a determination that the user identity credential is a service-level user identity credential, transmitting the user identity credential to the service-level user identity credential certifier node via the relying party node, wherein the service-level user identity credential certifier node is configured to perform user identity credential authentication for the user for the service; and   performing the service with the relying party node in response to reception of a receipt indicating that the user identity credential authentication succeeds from one of the legal user identity credential certifier node and the service-level user identity credential certifier node.   
     
     
         18 . The non-transitory computer readable medium according to  claim 17 , wherein the identity authentication system further comprises a relying party qualification certifier node, and the plurality of operations further comprise:
 obtaining relying party qualification information; and   transmitting the relying party qualification information to the relying party qualification certifier node, wherein the relying party qualification certifier node performs relying party qualification authentication; and   the obtaining an identity authentication assurance level corresponding to a service provided by a relying party comprises:   obtaining, in response to receiving a reply indicating that the relying party qualification authentication succeeds from the relying party qualification certifier node, the identity authentication assurance level corresponding to the service provided by the relying party.   
     
     
         19 . The non-transitory computer readable medium according to  claim 17 , wherein the determining, according to the identity authentication assurance level, a user identity credential used by a user for the service comprises:
 presenting candidate user identity credentials that match the identity authentication assurance level and the service provided by the relying party; and   receiving a candidate user identity credential selected by the user, and determining the candidate user identity credential selected by the user as the user identity credential used by the user for the service.   
     
     
         20 . The non-transitory computer readable medium according to  claim 17 , wherein the determining, according to the identity authentication assurance level, a user identity credential used by a user for the service comprises:
 searching a correspondence table of identity authentication assurance levels, services, and user identity credentials, to determine user identity credentials that match the identity authentication assurance level and the service provided by the relying party;   presenting the determined user identity credentials as candidate user identity credentials to the user of the service; and   determining one of the candidate user identity credentials selected by the user of the service as the user identity credential used by the user for the service.

Join the waitlist — get patent alerts

Track US2025080531A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.